cbcvebase.
CVE-2021-26291
published 2021-04-23

CVE-2021-26291: Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in…

PriorityP357critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
8.69%
94.5th percentile
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html

Affected

14 ranges
VendorProductVersion rangeFixed in
apachemaven< 3.8.13.8.1
apache_software_foundationapache_mavenApache Maven – 3.8.1
debianmaven< maven 3.8.6-1 (bookworm)maven 3.8.6-1 (bookworm)
jenkinsmaven>= 0 < 3.8.6-13.8.6-1
jenkinsmaven>= 0 < 3.8.6-13.8.6-1
jenkinsmaven>= 0 < 3.8.6-13.8.6-1
msrccbl2_javapackages-bootstrap_1.5.0-6_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_maven_3.8.1-1_on_cbl_mariner_1.0
oraclefinancial_services_analytical_applications_infrastructure8.0.6.0.0 – 8.0.9.0.0
oraclefinancial_services_analytical_applications_infrastructure8.1.0.0.0 – 8.1.2.0
oraclegoldengate_big_data_and_application_adapters
quarkusquarkus< 1.13.51.13.5

Detection & IOCsextracted from sources · hover to see the quote

  • Flag any Maven POM files or settings.xml that define repository URLs using the http:// scheme (non-SSL) rather than https://, as these are the exploitable configuration artifacts
  • Alert on Maven versions prior to 3.8.1 making outbound HTTP (port 80) connections to repository hosts during dependency resolution — Maven 3.8.1+ blocks this by default
  • ·Organizations using a repository manager (e.g., Nexus, Artifactory) to govern all repositories used in builds are NOT affected by this vulnerability, as the attack path requires Maven to directly follow external HTTP repository references from dependency POMs
  • ·The vulnerability is exploitable remotely over HTTP (not HTTPS); the protocol used is the key differentiator — only unencrypted HTTP repository references in POMs are the attack surface
  • ·Debian bullseye remains unpatched (open) as of the tracked advisory; fixed version is 3.8.6-1 in bookworm, forky, sid, and trixie

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_msrc9.1CRITICAL
vendor_oracle9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.